Central Bank Tightens Rules on Pix, Limiting Transfers from Unregistered Phones to R$200 per Transaction and R$1,000 per Day. Devices Must Be Validated for Larger Amounts While Banks Must Enhance Tracking, Blocking, and Fraud Prevention Mechanisms.
The Pix system now operates under specific restrictions for transfers made from phones or computers that have not yet been registered as trusted devices with financial institutions. On these devices, each operation is limited to R$200, while the total amount transferred throughout the day cannot exceed R$1,000.
The information was published by IstoÉ Dinheiro on August 18, 2026. The measures instituted by the Central Bank also include mandatory validation of devices for operations exceeding these limits, reinforcement of anti-fraud mechanisms, and requirements applicable to banks, cooperatives, and fintechs integrated into the national instant payment system.
Unregistered Phones and Computers Limited to R$200 per Pix

The restriction applies to devices that do not yet appear in the list of devices recognized by the customer’s bank. A Pix initiated from such a smartphone or computer can have a maximum value of R$200 per transaction.
-
Petrobras Loses Lawsuit Over R$850 Million in the Superior Court of Justice, Significantly Impacting State-Owned Company’s Financial Balance
-
Brazilian Company with 72-Year History Explores Production in Paraguay, Leveraging 1% Tax, Affordable Energy, and Lower Costs to Reexport Entire Output to Brazil
-
Brazil Activates Reciprocity Law in Response to Trump’s Tariff Increase, but Countermeasures Could Raise Costs for Machinery, Technology, Chemicals, and Other Imports, Economist Warns
-
Brazil Responds to U.S. Tariffs with Potential Trade Measures, Intellectual Property Suspensions, and Restriction of Royalties Following a 25% Tariff on Selected Products in July 2026
This measure links part of account security to the equipment used by the customer. Even if someone obtains credentials such as passwords and personal data, the absence of a previously recognized device creates an additional limitation for financial transactions.
Total Transfers from New Devices Cannot Exceed R$1,000 per Day
The limit applies not only individually per operation. All Pix transfers made during the same day from an unregistered device are subject to a cumulative ceiling of R$1,000.
The combination of these two limits prevents the R$200 restriction from being bypassed simply by making multiple sequential transfers of smaller amounts above the established daily limit.
Larger Transfers Require Device Registration and Pre-Validation
Customers who need to transfer amounts exceeding the limits set for unrecognized devices must register and validate the device with their financial institution.
This requirement becomes especially important when switching cellphones. A newly acquired device is not automatically considered a trusted device just because the user can access their bank account on it.
Biometrics, old device, or QR Code can be used for authorization
The registration process may vary between institutions. Among the mechanisms mentioned to authorize a new cellphone are facial biometrics validation, confirmation on a previously used device, and QR Code scanning at ATMs.
This procedure should be completed prior to making a large transfer when the device has not yet been recognized by the bank. Once validated, the device becomes part of the security framework associated with the customer’s account.
Rules aim to prevent fraud after cellphone theft and account breaches
The tightening of regulations follows the rise of Pix as the primary payment method in Brazil, which is responsible for transferring trillions of reais annually. This surge in popularity has also been accompanied by the evolution of fraud tactics.
Among the identified risks are social engineering, device theft, and account invasions through unauthorized devices. The financial limitations aim to minimize potential losses while preventive systems analyze transactions deemed unusual.
Central Bank strengthens DICT and Special Return Mechanism against fraud
The changes also affect tools used after identifying suspicious transactions. Requirements related to the Directory of Transactional Accounts, DICT, and the Special Return Mechanism, MED, have been reinforced to expedite tracking and hinder the flow of funds through accounts involved in fraud.
Institutions must implement quicker precautionary measures when fraud is suspected. The aim is to enhance the ability to identify involved receiving accounts and take action before the funds are moved again.
Suspicious funds can be blocked for up to 72 hours for analysis
The described mechanism allows funds in the receiving account to be subjected to provisional blocking for up to 72 hours when fraud is suspected.
During this time, security teams can analyze the transactions. This procedure seeks to increase the chances of preserving funds before they leave the account that received the disputed transfer.
Banks, cooperatives, and fintechs must comply with new security filters
These requirements are mandatory for institutions participating in the instant payment network, including banks, cooperatives, and fintechs.
Institutions must also implement verification filters designed to prevent atypical transactions outside the established limits. The described rule assigns financial responsibility to institutions that fail to apply these controls and allow irregular operations, regarding potential reimbursements to victims.
Requests for limit increases can take 24 to 48 hours
Users needing to transfer large amounts can also manage the limits set by their bank through the security section of the app.
Requests to increase limits take 24 to 48 hours to be processed, according to the mentioned regulation. This wait means that a requested increase may not be released immediately after the request is made.
Reduced limits between 8 PM and 6 AM remain in effect
The new restrictions for unregistered devices coexist with mechanisms that already affect certain payments made during the night. The reduced limits between 8 PM and 6 AM remain in place.
Larger transfer amounts may, therefore, encounter different restrictions depending on the device used, the limits set for the account, and the time at which the operation is requested.
Fraud victims can request activation of the MED with their bank
Customers who identify a fraud should notify their financial institution using its official channels and request the activation of the Special Refund Mechanism.
The MED aims to allow for the precautionary blocking of the funds available in the account that received the fraudulent transfer. The existence of the mechanism is not presented as a guarantee of full recovery of the funds, but rather as a tool to attempt to halt the movement of the amounts.
Device validation becomes a necessary step for transactions above the thresholds
The rules establish a clear separation between previously recognized devices and new ones. Without registration, the user remains subject to the limit of R$ 200 per transfer and R$ 1,000 per day on Pix.
Authorization for higher operations depends on the validation of the equipment with the bank, while DICT, MED, and precautionary blocks reinforce the tracking layer against suspicious movements. These requirements are mandatory for participating institutions in the system.
In your opinion, does limiting transfers made by unregistered cellphones help reduce fraud without overly complicating the everyday use of Pix? Share your thoughts in the comments.
